This is the page /.well-known/security.txt points to. Straight answers, no bug-bounty program to promise you.
If you've found a security issue in LeakWatch itself — the site, the API, the OAuth flow, anything that isn't a leak LeakWatch detected in someone else's repository — email me directly:
Include what you found, how to reproduce it, and what you think the impact is. I read this inbox myself — see /about for who that is.
In scope:
Out of scope:
I'm one person running this alongside my studies, so there's no bug-bounty payout and no SLA I can legally commit to — but I do take reports seriously and act on them fast. In practice: acknowledgment within a few days, and a fix or mitigation shipped well before any public disclosure. If I go quiet longer than that, follow up — it means the email got lost, not that it was ignored.
Please give me a reasonable window to fix an issue before writing about it publicly. I'm not going to threaten anyone who reports in good faith — testing against your own account, without touching other users' data, is fine.